Skip to content
Pre-Stuxnet uncovered: evidence of a shadow predecessor to the Iran cyberattack

Pre-Stuxnet uncovered: evidence of a shadow predecessor to the Iran cyberattack

Escudodigital April 28, 2026

Known as ‘Fast16,’ this tool operated with surgical discretion, inducing subtle, progressive errors to sabotage systems almost imperceptibly.

Stuxnet holds an almost mythical place in the history of cybersecurity. Discovered in 2010, this computer worm is considered t he first cyber weapon specifically created to cause physical damage to industrial infrastructures . It undeniably marked a before and after in the relationship between technology, state intelligence, and geopolitical conflicts. Stuxnet was extremely sophisticated malware specifically designed t o attack Siemens control systems used in uranium enrichment centrifuges in Iran.

Its goal was to discreetly sabotage the Iranian nuclear program by altering the operation of these machines while displaying false data indicating that everything was functioning correctly. In practice, this caused physical damage without the engineers detecting it in time.

The threat spread via USB drives in isolated facilities (without internet connection) and exploited several unknown vulnerabilities (zero-days). Although never officially confirmed, experts have always attributed its creation to the U.S.

The importance of Stuxnet was vital. It is estimated to have destroyed a significant portion of the centrifuges at the Natanz plant and delayed the Iranian nuclear program by several years . Thus, without direct military intervention, the risk of escalation in the Middle East was reduced.

However, the famous worm may not have been the first in these endeavors. Researchers from the security firm SentinelOne have discovered that there was earlier malware with a similar modus operandi created around 2005, known internally as 'Fast16' .

The finding suggests that Stuxnet was not an isolated project but the result of years of prior development in the field of advanced cyber sabotage. Thus, the origin of cyber operations against Iranian nuclear infrastructure would date back years before the famous worm. Hence, this would be a historical discovery that would modify the known chronology of cyberwarfare between states.

This 'new' but old malicious software acted in a more subtle manner . It did not directly destroy systems but manipulated calculations and simulations used in high-precision engineering and science environments . It did not seek immediate sabotage but introduced progressive errors that became difficult to detect .

On the surface, the malware appeared to be a normal Windows program. It included a system that allowed attackers to change its behavior in real-time and was linked to a component called 'Fast16', designed to move within computer networks using legitimate tools of the operating system itself.

Once active, this malware was capable of infiltrating important computer programs and modifying them while they were running , altering the results of the calculations they performed. Specifically, it was designed to manipulate highly advanced technical software used in scientific simulations, such as those employed to study explosions or physical impacts.

The name 'Fast16' had already appeared in a leak of U.S. National Security Agency (NSA) tools in 2017, where it was associated with espionage tools considered reliable within intelligence operations.

Consequently, while Sentinel stops short of a definitive attribution, researchers argue that the timing, technical sophistication, and subsequent references to the NSA strongly suggest that Fast16 was an initiative backed by the U.S. government, its military, or a close ally.

Stuxnet holds an almost mythical place in the history of cybersecurity. Discovered in 2010, this computer worm is considered t he first cyber weapon specifically created to cause physical damage to industrial infrastructures . It undeniably marked a before and after in the relationship between technology, state intelligence, and geopolitical conflicts. Stuxnet was extremely sophisticated malware specifically designed t o attack Siemens control systems used in uranium enrichment centrifuges in Iran.

Its goal was to discreetly sabotage the Iranian nuclear program by altering the operation of these machines while displaying false data indicating that everything was functioning correctly. In practice, this caused physical damage without the engineers detecting it in time.

The threat spread via USB drives in isolated facilities (without internet connection) and exploited several unknown vulnerabilities (zero-days). Although never officially confirmed, experts have always attributed its creation to the U.S.

The importance of Stuxnet was vital. It is estimated to have destroyed a significant portion of the centrifuges at the Natanz plant and delayed the Iranian nuclear program by several years . Thus, without direct military intervention, the risk of escalation in the Middle East was reduced.

However, the famous worm may not have been the first in these endeavors. Researchers from the security firm SentinelOne have discovered that there was earlier malware with a similar modus operandi created around 2005, known internally as 'Fast16' .

The finding suggests that Stuxnet was not an isolated project but the result of years of prior development in the field of advanced cyber sabotage. Thus, the origin of cyber operations against Iranian nuclear infrastructure would date back years before the famous worm. Hence, this would be a historical discovery that would modify the known chronology of cyberwarfare between states.

This 'new' but old malicious software acted in a more subtle manner . It did not directly destroy systems but manipulated calculations and simulations used in high-precision engineering and science environments . It did not seek immediate sabotage but introduced progressive errors that became difficult to detect .

On the surface, the malware appeared to be a normal Windows program. It included a system that allowed attackers to change its behavior in real-time and was linked to a component called 'Fast16', designed to move within computer networks using legitimate tools of the operating system itself.

Once active, this malware was capable of infiltrating important computer programs and modifying them while they were running , altering the results of the calculations they performed. Specifically, it was designed to manipulate highly advanced technical software used in scientific simulations, such as those employed to study explosions or physical impacts.

The name 'Fast16' had already appeared in a leak of U.S. National Security Agency (NSA) tools in 2017, where it was associated with espionage tools considered reliable within intelligence operations.

Consequently, while Sentinel stops short of a definitive attribution, researchers argue that the timing, technical sophistication, and subsequent references to the NSA strongly suggest that Fast16 was an initiative backed by the U.S. government, its military, or a close ally.

Become a premium member for free!

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Malware (2)

Platforms (1)

Tools (1)